The OpenNMS Group

First CVE: Feb 22, 2023Active for: 3 years
16
CVEs Published
More CVEs Published than 36% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by The OpenNMS Group as a CNA, 87.5% affect products that The OpenNMS Group develops as a vendor.

87.5%
12.5%
Self-reported: 14Third-party: 2

Of all the CVEs published that affect products developed by The OpenNMS Group, 46.7% are self-published by The OpenNMS Group as a CNA.

46.7%
53.3%
Self-published: 14Published by other CNAs: 16

Trends Over Time

The number and severity of CVEs published by The OpenNMS Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2023
3 years ago
Most Recent CVE
Jun 26, 2025
393 days ago

Top CVEs

All CVEs published by The OpenNMS Group as a CNA, regardless of affected vendor or product.

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solutio
Aug 14, 20238.037NOYES
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_
Aug 17, 20238.033NOYES
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code exe
Aug 17, 20238.824NONO
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection at
Aug 23, 20238.021NONO
XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which ca
Aug 11, 20236.121NONO
A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidentia
Mar 22, 20236.721NONO
Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade t
Feb 23, 20236.121NONO
Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confident
Feb 22, 20236.121NONO
Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow an attacke
Jun 26, 20256.920NONO
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confid
Feb 23, 20236.120NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA16 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (37.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (50.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required8 (50.0%)
Privileges Required
Low8 (50.0%)
High0 (0.0%)
None8 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by The OpenNMS Group as a CNA.

Media Mentions

Media articles that mention a CVE ID published by The OpenNMS Group as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs